DirectorySecurity Advisories
Sign In
Security Advisories

CGA-hxgx-rg66-hvqr

Published

Last updated

https://images.chainguard.dev/security/CGA-hxgx-rg66-hvqr
Package

mattermost-9

Latest Update
Not affected
Aliases
  • CVE-2024-24988
  • GHSA-6mx3-9qfh-77gj

Severity

4.3

Medium

CVSS V3

Summary

Mattermost denial of service through long emoji value

Description

Mattermost fails to properly validate the length of the emoji value in the custom user status, allowing an attacker to send multiple times a very long string as an emoji value causing high resource consumption and possibly crashing the server.

References

  • https://nvd.nist.gov/vuln/detail/CVE-2024-24988

Updates


Safe Source for Open Sourceâ„¢
Media KitContact Us
© 2024 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Product

Chainguard Images